Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
Discussion options

Hi,

I’ve noticed a high-severity vulnerability reported by Snyk in Pushy 0.15.4. The issue is related to the netty-handler@4.1.104.Final dependency (used in com.eatthepath:pushy@0.15.4io.netty:netty-codec-http2@4.1.104.Finalio.netty:netty-handler@4.1.104.Final).

As per the documentation, Pushy 0.15.4 is the latest version, and it depends on netty-handler@4.1.104.Final, which has the vulnerability.

I have a few questions:

  1. Is there a new version of Pushy planned that fixes this vulnerability?

  2. Or, can I exclude netty-handler@4.1.104.Final and try using a newer version of netty-handler that doesn't have the vulnerability? Would this be compatible with Pushy 0.15.4?

I’d appreciate your help and suggestions. Looking forward to your reply. Thanks.

You must be logged in to vote

Replies: 2 comments · 2 replies

Comment options

Can you please provide a link to the specific vulnerability?

To manage expectations, most of the time, these are false alarms. It's probably true that there's a vulnerability in netty-handler-4.1.104.Final, but netty-handler includes a lot of components that Pushy simply doesn't use. Often the vulnerabilities these scanners identify are in unrelated components.

You must be logged in to vote
0 replies
Comment options

This was the vulnerability reported
Snyk Link

You must be logged in to vote
2 replies
@jchambers
Comment options

Thank you. That does seem somewhat relevant, though I think the risk is very low because Pushy is generally talking to trusted servers. Still, we should update.

@anshumanS17
Comment options

@jchambers wanted to check in and see if there are any updates regarding this vulnerability. Do you have an estimated timeline for when the fix might be released?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
🙏
Q&A
Labels
None yet
2 participants
Morty Proxy This is a proxified and sanitized view of the page, visit original site.